From ec361a648d190847bd2e70b6c9ba0e95f8b92f64 Mon Sep 17 00:00:00 2001 From: "randomizedcoder dave.seddon.ca@gmail.com" Date: Mon, 24 Aug 2026 15:37:38 -0700 Subject: [PATCH] nixos/pdns-recursor: add api.enable to start the built-in webserver MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The `api.address`, `api.port` and `api.allowFrom` options render `webservice.{address,port,allow_from}`, but the module never set `webservice.webserver`, which defaults to false. The webserver therefore never started and those options had no effect — both the REST API and the Prometheus `/metrics` endpoint were unreachable no matter how `api.*` was configured. Add an `api.enable` option that sets `webservice.webserver`. It defaults to false, so existing configurations are unchanged; setting `api.enable = true` now makes the pre-existing `api.*` options functional. --- nixos/modules/services/networking/pdns-recursor.nix | 8 ++++++++ nixos/tests/pdns-recursor.nix | 10 ++++++++++ 2 files changed, 18 insertions(+) diff --git a/nixos/modules/services/networking/pdns-recursor.nix b/nixos/modules/services/networking/pdns-recursor.nix index bed9eb636086..76d5dc51a829 100644 --- a/nixos/modules/services/networking/pdns-recursor.nix +++ b/nixos/modules/services/networking/pdns-recursor.nix @@ -94,6 +94,13 @@ in ''; }; + api.enable = mkEnableOption '' + the built-in webserver. It serves the REST API (which additionally needs + an API key set via {option}`services.pdns-recursor.settings.webservice.api_key`) + and, at `/metrics`, statistics in Prometheus format. Without this the + `api.address`, `api.port` and `api.allowFrom` options have no effect, as + the webserver stays disabled''; + api.address = mkOption { type = types.str; default = "0.0.0.0"; @@ -222,6 +229,7 @@ in }; webservice = mkDefaultAttrs { + webserver = cfg.api.enable; address = cfg.api.address; port = cfg.api.port; allow_from = cfg.api.allowFrom; diff --git a/nixos/tests/pdns-recursor.nix b/nixos/tests/pdns-recursor.nix index 160d9a0fd2a0..c15ad62c0085 100644 --- a/nixos/tests/pdns-recursor.nix +++ b/nixos/tests/pdns-recursor.nix @@ -6,7 +6,9 @@ nodes.server = { services.pdns-recursor.enable = true; + services.pdns-recursor.api.enable = true; services.pdns-recursor.exportHosts = true; + services.pdns-recursor.settings.webservice.api_key = "supersecret"; networking.hosts."192.0.2.1" = [ "example.com" ]; }; @@ -17,5 +19,13 @@ with subtest("can resolve names"): assert "192.0.2.1" in server.succeed("host example.com localhost") + + with subtest("api is working"): + server.wait_for_open_port(8082) + server.succeed("curl -f -H 'X-API-Key: supersecret' http://localhost:8082/api/v1/servers") + server.fail("curl -f http://localhost:8082/api/v1/servers") + + with subtest("metrics are exported"): + assert "pdns_recursor_" in server.succeed("curl -f -H 'X-API-Key: supersecret' http://localhost:8082/metrics") ''; }